summaryrefslogtreecommitdiffstats
path: root/meta-networking
diff options
context:
space:
mode:
authorPeter Marko <peter.marko@siemens.com>2023-03-14 20:49:28 +0100
committerKhem Raj <raj.khem@gmail.com>2023-04-19 09:39:15 -0700
commit648912f72d3d85ef43ba5114953794faa1572bdf (patch)
treea259da8f1486f7a496ad5b9584428d20e8d72730 /meta-networking
parentdaa0c135a8919e7b7f427ce71528faec6ef7edd3 (diff)
downloadmeta-openembedded-648912f72d3d85ef43ba5114953794faa1572bdf.tar.gz
ntp: whitelist CVE-2019-11331
Links from https://nvd.nist.gov/vuln/detail/CVE-2019-11331 lead to conclusion that this is how icurrent ntp protocol is designed. New RFC is propsed for future but it will not be compatible with current one. See https://support.f5.com/csp/article/K09940637 Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Khem Raj <raj.khem@gmail.com>
Diffstat (limited to 'meta-networking')
-rw-r--r--meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb2
1 files changed, 2 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb b/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb
index 3ce2d77df7..5d2f05e925 100644
--- a/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb
+++ b/meta-networking/recipes-support/ntp/ntp_4.2.8p15.bb
@@ -27,6 +27,7 @@ SRC_URI = "http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-4.2/ntp-${PV}.tar.g
27SRC_URI[sha256sum] = "f65840deab68614d5d7ceb2d0bb9304ff70dcdedd09abb79754a87536b849c19" 27SRC_URI[sha256sum] = "f65840deab68614d5d7ceb2d0bb9304ff70dcdedd09abb79754a87536b849c19"
28 28
29# CVE-2016-9312 is only for windows. 29# CVE-2016-9312 is only for windows.
30# CVE-2019-11331 is inherent to RFC 5905 and cannot be fixed without breaking compatibility
30# The other CVEs are not correctly identified because cve-check 31# The other CVEs are not correctly identified because cve-check
31# is not able to check the version correctly (it only checks for 4.2.8 omitting p15 that makes the difference) 32# is not able to check the version correctly (it only checks for 4.2.8 omitting p15 that makes the difference)
32CVE_CHECK_IGNORE += "\ 33CVE_CHECK_IGNORE += "\
@@ -50,6 +51,7 @@ CVE_CHECK_IGNORE += "\
50 CVE-2016-7433 \ 51 CVE-2016-7433 \
51 CVE-2016-9310 \ 52 CVE-2016-9310 \
52 CVE-2016-9311 \ 53 CVE-2016-9311 \
54 CVE-2019-11331 \
53" 55"
54 56
55 57